Skip to main content
AVOID.NET

Famous Chollima ClickFake Interview Campaign (PylangGhost / GolangGhost)

avoid.net/famous-chollima-clickfake-interview-campaign-pylangghost-golangghost0/100·93% conf.
[AI-DRAFTED · AWAITING VERIFICATION]

Auto-generated score, not yet verified against the scoring model. Under review — treat as indicative, not a verdict.

anchored·pA3Wqi…g5Nw

Summary

The ClickFake Interview campaign is an active cyberespionage operation attributed with high confidence to Famous Chollima, a North Korean state-sponsored threat actor linked to the Reconnaissance General Bureau and the broader Lazarus Group umbrella. Targets are cryptocurrency and Web3 professionals lured via fake job recruitment on LinkedIn, Telegram, and Discord, then induced through a ClickFix social engineering trick to execute terminal commands that install the PylangGhost (Windows) or GolangGhost (macOS) remote access trojans, which steal credentials from over 80 browser extensions including cryptocurrency wallets and password managers. The campaign, documented since at least mid-2024 in its current form, evolved from the earlier Contagious Interview / DEV#POPPER lineage and represents a continuing North Korean strategy of using employment lures to harvest crypto assets.

Connected Entities

13 entities · 60 linked investigations
Organizations
TraderTraitor / UNC48990Kraken62Safe{Wallet}68Patrick Yarmoch (FBI Agent — Crypto Theft)EthereumTetherNorth Korea Lazarus Group — H1 2026 Systematic Crypto Theft CampaignPhantom WalletFamous Chollima ClickFake Interview Campaign (PylangGhost / GolangGhost)
Protocols
BlockFiUniswap
Tokens
CoinbaseKuCoin
Relationships
  • Ethereummentioned withCoinbase(60%)
  • KuCoinmentioned withUniswap(60%)
  • KuCoinmentioned withEthereum(60%)
  • Phantom Walletmentioned withEthereum(70%)
  • TraderTraitor / UNC4899mentioned withSafe{Wallet}(70%)
  • TraderTraitor / UNC4899mentioned withEthereum(80%)
  • Phantom Walletmentioned withCoinbase(60%)
  • Safe{Wallet}mentioned withEthereum(80%)
  • Famous Chollima ClickFake Interview Campaign (PylangGhost / GolangGhost)mentioned withPatrick Yarmoch (FBI Agent — Crypto Theft)(85%)
  • Famous Chollima ClickFake Interview Campaign (PylangGhost / GolangGhost)mentioned withTraderTraitor / UNC4899(80%)
  • + 20 more
Have evidence about Famous Chollima ClickFake Interview Campaign (PylangGhost / GolangGhost)?
0
Accepted
1
Under review
0
Rejected / revoked

Community submissions

  • Under reviewincriminatingWayback pending8/4/2026, 4:19:33 PM

    Cisco Talos July 2026 technical analysis of PylangGhost — the Python Windows RAT variant targeting Web3 professionals, a new capability not previously documented on the existing investigation page

    avoid-scout

Timeline(11 events)

December 2022

Contagious Interview campaign begins, targeting software developers via fake GitHub-hosted coding assessments. Attributed to Famous Chollima / Lazarus Group.

Sekoia Research / Palo Alto Networks

November 2023

Palo Alto Networks publicly documents the Contagious Interview campaign for the first time.

The Hacker News

June 2024

Campaign evolves; GolangGhost backdoor and FrostyFerret macOS stealer first observed in ongoing fake interview operations.

Cisco Talos

21 February 2025

Lazarus Group (TraderTraitor) steals approximately $1.5 billion USD from Bybit via compromise of Safe{Wallet} developer infrastructure — the largest crypto theft on record.

FBI IC3 PSA

26 February 2025

FBI IC3 releases public service announcement attributing the Bybit theft to North Korea's Lazarus Group (TraderTraitor) and publishing 52 associated Ethereum wallet addresses.

FBI Internet Crime Complaint Center

21 March 2025

Sekoia distributes private FLINT report codenaming the evolved campaign ClickFake Interview, documenting GolangGhost, FrostyFerret, and the shift to ClickFix social engineering and CeFi targeting.

Sekoia

April 2025

Sekoia publicly releases ClickFake Interview research; The Hacker News and Infosecurity Magazine cover findings. Campaign linked to 40+ companion domains registered in April 2025.

The Hacker News

May 2025

Cisco Talos identifies PylangGhost, a Python-based Windows RAT functionally equivalent to GolangGhost, marking a new malware family exclusive to Famous Chollima in the ClickFake campaign.

Cisco Talos

11 March 2026

Microsoft Security Blog publishes detailed analysis of the Contagious Interview malware delivery campaign including BeaverTail, InvisibleFerret, and related tooling.

Microsoft Security Blog

20 July 2026

SOCRadar Threat Research Unit publishes updated analysis of the ClickFake Interview campaign documenting PylangGhost and GolangGhost targeting Web3 professionals, with new infrastructure observations including Nuitka-compiled variants.

SOCRadar

22 July 2026

GBHackers and Infosecurity Magazine publish coverage of the active ClickFake Interview campaign deploying PylangGhost and GolangGhost RATs.

GBHackers / Infosecurity Magazine
Provenance & Audit Trail

Decision Log

This investigation is cryptographically anchored to the Solana blockchain (3 events). 18 of 18 cited source URLs have an Internet Archive snapshot.

model: claude-sonnet-4-6

generated: 8/4/2026, 12:17:27 PM

last updated: 8/26/2026, 11:09:21 AM

4 views

avoid.net — verified advice for a post-truth world